Concepts
Continuation C
The computation from its current point onward — what can still happen from here. Ato's unit of work is the continuation, not the repository, the manifest, or a state snapshot.
Contract K
The author-chosen observable conditions that decide whether a future computation counts as the same resumable point. A Capsule is identified by its Contract: what must be reproduced to count as the same continuation point, never how it was built.
Capsule
The addressable continuation identity defined by K. Verification evidence records that a concrete attempt satisfied K — it travels with the Capsule but is not part of its identity. One Capsule can be reached by many Derivations.
Derivation D
An executable route that attempts to produce a continuation satisfying K. Derivations are addressed separately from Contracts, so routes can be compared, retried, and replaced without changing what the Capsule means.
Formation
The process that freezes the source, proposes candidate Derivations, executes each on a compatible Runtime, observes the candidate against K, and keeps what verifies. Try it in the Getting started guide.
Run
A live continuation resumed from a Capsule. Runs are mutable and advance; sealing a point produces a new Capsule.
Runner / Runtime
Where a Derivation executes. Runners provide Runtimes with specific capabilities; Formation only schedules a Derivation where its requirements are met. Phase 1 admits --runtime local.
Binding
How a logical need maps to a concrete endpoint: a workspace path becomes a content address, an exported port becomes a host endpoint selected by the Runner. Bindings are resolved per run, never baked into identity.
Out of scope here
The Runtime Network, browser-contract verification, and model-guided derivation decisions are experimental. They build on these concepts but are not required to form and use a Capsule locally.
Authoring reference: capsule.toml.